Security & Compliance
Model training is disabled by default.
Encryption at rest and in transit, LGPD-oriented processes, and granular workspace access controls.

Infrastructure
What is enabled and what is an Enterprise option.
The matrix keeps default controls, contractual options, and roadmap items separate.
| Control | Scope | Default | Enterprise |
|---|---|---|---|
AES-256 EncryptionAES-256 for stored objects, with dedicated KMS or BYOK according to workspace policy. | Storage | Enabled | KMS / BYOK |
TLS in transitCommunication between the browser and service endpoints uses TLS in transit. | Traffic | Enabled | Additional policies |
Access controlRBAC with permissions per workspace, per user, and per resource. Every action is logged. | Workspace | RBAC | SSO / SAML |
2FA Authentication2FA available for all plans. SSO/SAML for Enterprise. | Account | 2FA | SSO / SAML |
Audit logsComplete verification of all operations. Who accessed, when, and what. | Operations | Product records | Extended governance |
Backup and DRAutomatic backups with configurable retention. Incident recovery without data loss. | Continuity | Recovery procedures | Contractual policy |
Data handling
How we handle your data
From upload to deletion, each category has a purpose and an applicable policy.
Uploaded audio
Processed by the selected ASR engine and retained according to workspace settings until user deletion or the applicable policy.
Transcriptions
Stored encrypted in your workspace. Accessible only by you and authorized members. Exportable at any time.
Personal data
We only collect what is necessary to operate the service (email, name, plan). Never sold. Never shared for marketing.
AI models
Training opt-in is disabled by default. Processing by selected AI providers follows their enterprise terms and applicable retention policies.
Integrations
Minimal and revocable access. We connect with Google Drive, Dropbox, Zoom, and Slack — but only access what you authorize, when you authorize it.
Compliance
LGPD by design
The product was built with LGPD processes in mind.
- Right of accessArt. 18, I
- Right of correctionArt. 18, III
- Right of deletionArt. 18, VI
- Right of portabilityArt. 18, V
- Right to revoke consentArt. 18, IX
- Right to information on sharingArt. 18, VII
Certifications
Certifications and roadmap
Implemented controls are not presented as independent certifications.
LGPD processes
Operational practice and documentation
AES-256 at rest
Implemented control
TLS in transit
Implemented control
SOC 2 Type II
In preparation
ISO 27001
Roadmap
Frequently asked questions
Security questions
Have questions about security?
For DPA requests, subprocessor lists, or security reviews, write directly to the responsible team.
security@transcriwise.com